Выполните скрипт в AVZ (AVZ запускать от имени Администратора по правой кнопке мыши)
Код:
begin
ShowMessage('Внимание! Перед выполнением скрипта AVZ автоматически закроет все сетевые подключения.' + #13#10 + 'После перезагрузки компьютера подключения к сети будут восстановлены в автоматическом режиме.');
ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
SearchRootkit(true, true);
SetAVZGuardStatus(true);
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ovokza\faeh.exe', 'MBAM: Trojan.Crypt.NKN');
QuarantineFile('C:\Users\Alexandr\AppData\Local\Temp\0029cc82.exe', 'MBAM: Malware.Generic');
QuarantineFile('C:\Users\Alexandr\AppData\Local\Temp\004adc4b.exe', 'MBAM: Malware.Generic');
QuarantineFile('C:\Users\Alexandr\AppData\Local\Temp\267.exe', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Users\Alexandr\AppData\Local\Temp\308.exe', 'MBAM: Trojan.Crypt.NKN');
QuarantineFile('C:\Users\Alexandr\AppData\Local\Temp\325.exe', 'MBAM: Trojan.Agent.EDTT');
QuarantineFile('C:\Users\Alexandr\AppData\Local\Temp\345.exe', 'MBAM: Trojan.Agent.EDSR');
QuarantineFile('C:\Users\Alexandr\AppData\Local\Temp\bot1.exe', 'MBAM: Heuristics.Shuriken');
QuarantineFile('C:\Users\Alexandr\AppData\Local\Temp\bot4.exe', 'MBAM: Heuristics.Shuriken');
QuarantineFile('C:\Users\Alexandr\AppData\Local\Temp\rtscom.exe', 'MBAM: Backdoor.Messa');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Aciz\voowd.exe', 'MBAM: Trojan.Zbot');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Afedhy\toelr.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ahtuel\ewid.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Akaq\ofse.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Arox\kiat.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Artep\tebei.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Arun\icti.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Atsy\uphex.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Beex\hunug.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Bice\seazi.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Bowuyw\olefu.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Caowp\osegy.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ceutqe\raos.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ciyh\tofu.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Codyam\guis.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Cyof\avac.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Cytaah\kado.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Dobo\yhoq.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ecti\merym.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Edcyvo\evnuu.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Edsyic\papi.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Edydc\fauc.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Efnuov\iqdui.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Egfuyx\ysku.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ekzero\boif.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Elfi\ekqey.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Elsi\qauds.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ennaci\erdei.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Eqexoh\bieww.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Eqofs\anuc.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Erzi\waep.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Esanac\zaly.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Evke\elkaa.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Fipit\axbao.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Fyety\ozyfe.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Giin\izbo.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Hixuum\unipb.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Hohoo\ehavv.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Hyemka\etaza.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Hyydro\nuxyf.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ibpy\quow.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Icacgy\qeny.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Icro\reoz.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ifbecu\ykfy.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Igmyyq\vyato.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Iluk\ryhug.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Imbuo\umut.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Imqyp\ivxus.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Iqqef\itgu.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ivzau\amez.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Iwaqo\ytif.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ixyvew\irpiv.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Koeb\yqryo.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Liofi\iqqe.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Luih\gayk.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Maaxlo\wyur.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Meofx\qoude.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Meso\ibifi.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Meto\beilh.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Miwyz\uwov.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Motu\poiw.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Neod\ycsu.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Niixi\uzog.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Nyuh\koeno.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Nyyc\ebqo.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Obzau\asifs.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ocmiqu\yvwy.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ocnot\uqxay.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ofedl\wysuy.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ofyxuz\byih.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ogofmu\muaqk.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ohmue\laiss.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Olod\zeem.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Omvofe\imip.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Omyv\xiiwg.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Onan\ryyf.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Onlu\ennac.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Opivc\agco.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Opruo\upes.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Oqce\sexa.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Orew\ofnae.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Oszyl\owhu.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Oterqy\died.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Oxpy\omim.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Paot\ysegg.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Puatf\nyfi.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Puwuki\iftou.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Puzi\xehyi.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Qokyib\dysux.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Quowmo\ibuq.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Qyorka\quocy.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Qyowuv\udik.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Roru\xuasc.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Royfe\aphap.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ruqi\taoxu.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Sekeka\pevi.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Suyq\qeyk.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Syyzup\voza.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Tawo\oqed.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Teen\eteg.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Toelv\huaq.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Uded\rawi.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Uhmu\biqy.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Uqnex\nofu.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Urmeo\xosue.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ururq\eblus.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Uvaq\ohxu.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Uxefen\adaw.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Uxica\iteci.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Uxney\hukya.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Uxomi\opigu.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Vefud\moemi.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Vexod\itlo.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Vihipa\ybde.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Vuov\oqac.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Vuowvu\caty.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Wasi\ilfys.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Werii\ohfal.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Wobook\zuagr.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Womyca\zeosy.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Wuqi\ubkiu.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Xais\awoze.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Xisemi\yrru.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Xosu\wobo.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ybewse\egpui.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Yfny\agsaf.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Yftoyk\kiatu.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ykbot\ezun.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Yludo\cyofr.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ymeru\ekotn.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Ynxe\irlo.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Yposo\humow.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Yqvuf\filuw.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Yvatu\etam.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Yzwie\saaw.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Zaom\osli.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Zaveaz\itaz.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Roaming\Zeamsu\omesa.exe', 'MBAM: Spyware.Zeus');
QuarantineFile('C:\Users\Alexandr\AppData\Local\wsearch\wsearch.exe', 'MBAM: Trojan.Wsearch');
QuarantineFile('C:\Windows\System32\MSDCSC\msdcsc.exe', 'MBAM: Backdoor.Agent.DC');
QuarantineFile('C:\Windows\SysWOW64\MSDCSC\msdcsc.exe', 'MBAM: Backdoor.Agent.DC');
QuarantineFile('C:\Users\Alexandr\AppData\Local\Temp\00007389.exe', 'MBAM: Trojan.Agent.Gen');
QuarantineFile('C:\Users\Alexandr\AppData\Local\Temp\00007963.exe', 'MBAM: Trojan.Agent.Gen');
QuarantineFile('C:\Users\Alexandr\Local Settings\Application Data\Temp\00007389.exe', 'MBAM: Trojan.Agent.Gen');
QuarantineFile('C:\Users\Alexandr\Local Settings\Application Data\Temp\00007963.exe', 'MBAM: Trojan.Agent.Gen');
QuarantineFile('C:\Users\Alexandr\Desktop\1365.tmp', 'MBAM: Trojan.FileFill');
QuarantineFile('C:\Program Files (x86)\Compan\OldProd\alene.vbs', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compan\OldProd\dancedance.txt', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compan\OldProd\lidogeneratsiya.bat', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compan\OldProd\lopera.txt', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compan\OldProd\midiiiia.bat', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compan\OldProd\pozvoni.vbs', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compans\OldProi\abdula.txt', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compans\OldProi\bieberfalls.bat', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compans\OldProi\goingdown.bat', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compans\OldProi\moimalish.vbs', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compans\OldProi\rotokantrop.txt', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compans\OldProi\spiahdetka.vbs', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compans\OldProi\Uninstall.exe', 'MBAM: Trojan.Agent.VBS');
QuarantineFile('C:\Program Files (x86)\Compans\OldProi\Uninstall.ini', 'MBAM: Trojan.Agent.VBS');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ovokza\faeh.exe');
DeleteFile('C:\Users\Alexandr\AppData\Local\Temp\0029cc82.exe');
DeleteFile('C:\Users\Alexandr\AppData\Local\Temp\004adc4b.exe');
DeleteFile('C:\Users\Alexandr\AppData\Local\Temp\267.exe');
DeleteFile('C:\Users\Alexandr\AppData\Local\Temp\308.exe');
DeleteFile('C:\Users\Alexandr\AppData\Local\Temp\325.exe');
DeleteFile('C:\Users\Alexandr\AppData\Local\Temp\345.exe');
DeleteFile('C:\Users\Alexandr\AppData\Local\Temp\bot1.exe');
DeleteFile('C:\Users\Alexandr\AppData\Local\Temp\bot4.exe');
DeleteFile('C:\Users\Alexandr\AppData\Local\Temp\rtscom.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Aciz\voowd.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Afedhy\toelr.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ahtuel\ewid.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Akaq\ofse.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Arox\kiat.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Artep\tebei.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Arun\icti.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Atsy\uphex.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Beex\hunug.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Bice\seazi.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Bowuyw\olefu.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Caowp\osegy.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ceutqe\raos.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ciyh\tofu.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Codyam\guis.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Cyof\avac.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Cytaah\kado.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Dobo\yhoq.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ecti\merym.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Edcyvo\evnuu.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Edsyic\papi.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Edydc\fauc.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Efnuov\iqdui.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Egfuyx\ysku.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ekzero\boif.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Elfi\ekqey.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Elsi\qauds.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ennaci\erdei.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Eqexoh\bieww.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Eqofs\anuc.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Erzi\waep.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Esanac\zaly.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Evke\elkaa.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Fipit\axbao.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Fyety\ozyfe.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Giin\izbo.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Hixuum\unipb.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Hohoo\ehavv.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Hyemka\etaza.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Hyydro\nuxyf.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ibpy\quow.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Icacgy\qeny.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Icro\reoz.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ifbecu\ykfy.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Igmyyq\vyato.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Iluk\ryhug.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Imbuo\umut.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Imqyp\ivxus.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Iqqef\itgu.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ivzau\amez.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Iwaqo\ytif.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ixyvew\irpiv.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Koeb\yqryo.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Liofi\iqqe.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Luih\gayk.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Maaxlo\wyur.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Meofx\qoude.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Meso\ibifi.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Meto\beilh.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Miwyz\uwov.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Motu\poiw.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Neod\ycsu.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Niixi\uzog.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Nyuh\koeno.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Nyyc\ebqo.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Obzau\asifs.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ocmiqu\yvwy.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ocnot\uqxay.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ofedl\wysuy.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ofyxuz\byih.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ogofmu\muaqk.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ohmue\laiss.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Olod\zeem.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Omvofe\imip.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Omyv\xiiwg.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Onan\ryyf.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Onlu\ennac.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Opivc\agco.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Opruo\upes.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Oqce\sexa.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Orew\ofnae.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Oszyl\owhu.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Oterqy\died.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Oxpy\omim.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Paot\ysegg.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Puatf\nyfi.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Puwuki\iftou.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Puzi\xehyi.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Qokyib\dysux.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Quowmo\ibuq.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Qyorka\quocy.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Qyowuv\udik.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Roru\xuasc.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Royfe\aphap.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ruqi\taoxu.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Sekeka\pevi.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Suyq\qeyk.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Syyzup\voza.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Tawo\oqed.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Teen\eteg.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Toelv\huaq.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Uded\rawi.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Uhmu\biqy.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Uqnex\nofu.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Urmeo\xosue.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ururq\eblus.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Uvaq\ohxu.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Uxefen\adaw.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Uxica\iteci.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Uxney\hukya.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Uxomi\opigu.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Vefud\moemi.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Vexod\itlo.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Vihipa\ybde.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Vuov\oqac.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Vuowvu\caty.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Wasi\ilfys.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Werii\ohfal.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Wobook\zuagr.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Womyca\zeosy.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Wuqi\ubkiu.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Xais\awoze.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Xisemi\yrru.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Xosu\wobo.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ybewse\egpui.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Yfny\agsaf.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Yftoyk\kiatu.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ykbot\ezun.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Yludo\cyofr.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ymeru\ekotn.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Ynxe\irlo.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Yposo\humow.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Yqvuf\filuw.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Yvatu\etam.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Yzwie\saaw.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Zaom\osli.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Zaveaz\itaz.exe');
DeleteFile('C:\Users\Alexandr\AppData\Roaming\Zeamsu\omesa.exe');
DeleteFile('C:\Users\Alexandr\AppData\Local\wsearch\wsearch.exe');
DeleteFile('C:\Users\Alexandr\AppData\Local\Temp\00007389.exe');
DeleteFile('C:\Users\Alexandr\AppData\Local\Temp\00007963.exe');
DeleteFile('C:\Users\Alexandr\Local Settings\Application Data\Temp\00007389.exe');
DeleteFile('C:\Users\Alexandr\Local Settings\Application Data\Temp\00007963.exe');
DeleteFile('C:\Users\Alexandr\Desktop\1365.tmp');
DeleteFile('C:\Program Files (x86)\Compan\OldProd\alene.vbs');
DeleteFile('C:\Program Files (x86)\Compan\OldProd\dancedance.txt');
DeleteFile('C:\Program Files (x86)\Compan\OldProd\lidogeneratsiya.bat');
DeleteFile('C:\Program Files (x86)\Compan\OldProd\lopera.txt');
DeleteFile('C:\Program Files (x86)\Compan\OldProd\midiiiia.bat');
DeleteFile('C:\Program Files (x86)\Compan\OldProd\pozvoni.vbs');
DeleteFile('C:\Program Files (x86)\Compan\OldProd\Uninstall.exe');
DeleteFile('C:\Program Files (x86)\Compan\OldProd\Uninstall.ini');
DeleteFile('C:\Program Files (x86)\Compans\OldProi\abdula.txt');
DeleteFile('C:\Program Files (x86)\Compans\OldProi\bieberfalls.bat');
DeleteFile('C:\Program Files (x86)\Compans\OldProi\goingdown.bat');
DeleteFile('C:\Program Files (x86)\Compans\OldProi\moimalish.vbs');
DeleteFile('C:\Program Files (x86)\Compans\OldProi\rotokantrop.txt');
DeleteFile('C:\Program Files (x86)\Compans\OldProi\spiahdetka.vbs');
DeleteFile('C:\Program Files (x86)\Compans\OldProi\Uninstall.exe');
DeleteFile('C:\Program Files (x86)\Compans\OldProi\Uninstall.ini');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\92ac0b0058c0f222');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djc');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczup');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmn');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnopt');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevz');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbf');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkc');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmc');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmcaim');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmcaimnvc');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmcaimnvchuh');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmcaimnvchuhchu');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmcaimnvchuhchuijv');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmcaimnvchuhchuijvdur');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmcaimnvchuhchuijvdurkmj');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmcaimnvchuhchuijvdurkmjrpm');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmcaimnvchuhchuijvdurkmjrpmbgh');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmcaimnvchuhchuijvdurkmjrpmbghmxa');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmcaimnvchuhchuijvdurkmjrpmbghmxatlp');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\djczupwmnoptevzdbfkkclmcaimnvchuhchuijvdurkmjrpmbghmxatlpdcm');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\fypzpdt');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\ms');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\msconfig');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\niwnnbr');
RegKeyDel('HKLM', 'software\microsoft\shared tools\msconfig\startupreg\system.exe');
RegKeyDel('HKCU', 'software\microsoft\shared tools\msconfig\startupreg\{575524D7-DA66-52AB-A52B-45D3CCF0FEEE}');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Компьютер перезагрузится.
Выполните скрипт в AVZ
Код:
begin
CreateQurantineArchive('c:\quarantine.zip');
end.
Отправьте c:\quarantine.zip при помощи этой формы
|